A-LIGN

A-LIGN

Automates cybersecurity compliance audits with software

Overview

A-LIGN is a cybersecurity and compliance solutions provider that combines automated software with audit services. Its flagship platform, A-SCEND, automates the audit process by handling evidence collection, policy management, and real-time compliance assessments, helping clients become audit-ready in about half the time and saving hundreds of hours. The company earns revenue from software sales and audit services and uses a single-provider model to offer an end-to-end compliance solution that scales with a business. A-LIGN differentiates itself through its extensive audit experience and claims to have issued more SOC 2 reports than any other provider. Its goal is to simplify and accelerate the process of achieving and maintaining cybersecurity compliance for organizations of all sizes.

About A-LIGN

Simplify's Rating
Why A-LIGN is rated
B-
Rated B on Competitive Edge
Rated B on Growth Potential
Rated C on Differentiation

Industries

Consulting

Enterprise Software

Cybersecurity

Company Size

501-1,000

Company Stage

Acquired

Total Funding

$54.5M

Headquarters

Tampa, Florida

Founded

2009

Get referred to A-LIGN

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • August 19, 2026 RealCISO partnership embeds auditors directly into customer workflows.
  • February 25, 2026 London expansion followed 45% new-bookings growth across EMEA.
  • May 21, 2026 Optro-Crowe deal and Kiteworks partnership expand CMMC demand.

What critics are saying

  • July 13, 2026 DoW CMMC review delays assessments, freezing DIB pipeline into 2027.
  • Optro, Crowe, and Kiteworks bundle readiness plus assessment, squeezing A-LIGN pricing.
  • Compliance platforms and AI automation commoditize audits, threatening A-LIGN's core assessment margin.

What makes A-LIGN unique

  • Sept. 1, 2026 Pathfynder acquisition adds offensive security under one roof.
  • A-SCEND EvidenceIQ launched March 2026, automating evidence scoring and reuse.
  • A-LIGN leads SOC 2 and CMMC assessments across 6,400 customers worldwide.

Help us improve and share your feedback! Did you find this helpful?

Funding

Total Funding

$54.5M

Above

Industry Average

Funded Over

2 Rounds

Buyout funding comparison data is currently unavailable. We're working to provide this information soon!
Buyout Funding Comparison
Coming Soon

Benefits

Wellness Program

Mental Health Support

Gym Membership

Phone/Internet Stipend

Conference Attendance Budget

Family Planning Benefits

Fertility Treatment Support

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

-1%

2 year growth

-1%
PR Newswire
Sep 1st, 2026
A-LIGN acquires Pathfynder, adding offensive security depth for enterprises with complex security needs.

A-LIGN acquires Pathfynder, adding offensive security depth for enterprises with complex security needs. Sep 01, 2026, 16:00 ET Veteran-owned elite cybersecurity team expands A-LIGN's ability to help organizations move beyond compliance and stay ahead of real-world attackers TAMPA, Fla., Sept. 1, 2026 /PRNewswire/ - A-LIGN, the leading cybersecurity compliance company, today announced its acquisition of Pathfynder, a specialized offensive and defensive cybersecurity firm. The acquisition expands A-LIGN's service offerings for enterprises looking to strengthen their security posture and reduce the risk of cyberattacks. The acquisition comes as enterprises face an increasingly costly, fast-moving, and AI-accelerated threat landscape. As attackers grow more sophisticated and persistent, compliance alone is no longer enough. Countering AI-enabled attacks takes both skilled people and advanced technology working together, and organizations need to know if their defenses can hold up against real adversaries. Pathfynder, a veteran-owned company, employs a team of elite specialists with decades of cybersecurity, military, and intelligence community experience. They provide technical offensive and defensive cybersecurity services including network, cloud, and web application penetration testing, red team and adversary emulation, testing of complex and emerging capabilities, and forensics and incident response. "Since our inception, A-LIGN has believed in the power of combined compliance and technical cybersecurity services under one roof," said Scott Price, CEO of A-LIGN. "The acquisition of Pathfynder enables A-LIGN to offer customers advanced offensive security services delivered by a team that operates independently from our assurance and assessment practice while leveraging institutional knowledge of the customer to enhance the cybersecurity services. Pathfynder will remain a highly experienced and specialized team under the A-LIGN parent brand, maintaining its brand as Pathfynder by A-LIGN. This structure preserves the independence between A-LIGN's assurance and assessment teams and Pathfynder's penetration testers to protect the integrity of both functions. For A-LIGN's more than 6,400 existing customers, it also means access to advanced, real-world security testing from a trusted partner, without the friction of managing another vendor relationship. "We are excited to join the A-LIGN team and bring our trusted expertise and proven capabilities to their existing suite of services," said DJ Fuller, founder of Pathfynder. "We share the same core values and mission: helping companies close security gaps and meet regulatory requirements, so they can reduce the risk of financial and reputational damage from a cyberattack." About A-LIGN A-LIGN is the leading cybersecurity compliance partner, trusted by over 6,400 organizations worldwide to navigate the complexities of compliance, audit, and risk. With a tech-enabled delivery model and deep domain expertise, A-LIGN has completed more than 36,000 audits. It is the #1 issuer of SOC 2 reports and a top three FedRAMP assessor. Founded in 2009, A-LIGN delivers high-quality, efficient audits across frameworks including SOC 2, ISO 27001, FedRAMP, CMMC, ISO 42001, PCI, and HITRUST. To learn more, visit: https://www.a-lign.com. SOURCE A-LIGN

RealCISO
Aug 19th, 2026
A-LIGN and RealCISO partner to connect auditors directly into the compliance platform.

A-LIGN and RealCISO partner to connect auditors directly into the compliance platform. Joint customers can run assessments, collect evidence from live systems, and work with their A-LIGN audit team in one place - no separate auditor portal, no evidence re-uploads BOSTON, MA - August 19, 2026 - RealCISO, the compliance intelligence platform used by more than 3,000 organizations, and A-LIGN, the cybersecurity compliance firm behind more than 36,000 audits for 6,400+ clients worldwide, today announced a strategic partnership that removes the most expensive handoff in compliance: the jump from "audit ready" to audited. Today, most organizations prepare for an audit in one platform, then export everything into the auditor's portal - re-uploading evidence, answering duplicate requests, and reconciling versions across two systems. That handoff adds weeks to every engagement and is the single biggest source of audit friction for security and compliance teams. This partnership eliminates it. As part of the rollout, A-LIGN auditors will work directly inside RealCISO: reviewing and accepting evidence, issuing follow-up requests, and communicating with the customer's team in the same platform where the compliance program already lives. The partnership delivers: * In-platform auditor connection. A-LIGN audit teams get scoped access inside RealCISO to review evidence, post requests, and resolve questions in-app - customers never leave the platform they work in every day. * Audit-grade functionality. Point-in-time revision snapshots seal assessment answers for defensible audit trails, evidence management tracks expiration and quality, and reports carry immutable version history. One evidence set maps across SOC 2, ISO 27001, HIPAA, NIST CSF 2.0, and other frameworks - no duplicate work per audit. * Evidence from live systems. RealCISO's newest release includes 15 integrations running 155 automated evidence collectors and 386 control tests on a 12-hour cadence - spanning AWS, Azure, Google Cloud, Microsoft 365, Google Workspace, Okta, Microsoft Intune, Jamf, Kandji, CrowdStrike, Qualys, Tenable, and ConnectWise. Auditors see evidence pulled from production systems, not screenshots collected months earlier. * One system, start to finish. From first assessment to final report, the entire engagement runs in a single platform - with AI-assisted evidence mapping doing the tedious work of linking uploads to controls. "Every compliance platform says 'audit ready.' Then the audit starts and your team spends six weeks re-uploading evidence into someone else's portal," said Brian Haugli, Co-Founder of RealCISO. "That's the part we're killing. With A-LIGN working inside RealCISO, the assessment, the evidence, and the auditor are finally in one system. Our customers keep working. A-LIGN gets evidence pulled straight from live systems - not a screenshot from three quarters ago." The in-platform auditor connection begins rolling out to joint RealCISO and A-LIGN customers as part of the partnership. About RealCISO RealCISO is a cloud-based compliance intelligence platform used by more than 3,000 organizations, including MSPs, MSSPs, vCISO consultants, and enterprise GRC teams. Built on a connected compliance data graph linking controls, risks, evidence, vendors, policies, and people, RealCISO tracks security maturity over time - not just point-in-time compliance status. RealCISO was named a G2 Summer 2026 High Performer and the #1-ranked vCISO platform. About A-LIGN A-LIGN is a cybersecurity compliance partner trusted by more than 6,400 organizations worldwide, with over 36,000 audits completed. A-LIGN is the #1 issuer of SOC 2 reports globally, a top-3 FedRAMP assessor, an authorized CMMC C3PAO, and a leading HITRUST assessor, delivering audits and assessments across SOC 1 and SOC 2, ISO 27001 and ISO 42001, HITRUST, HIPAA, PCI DSS, and federal frameworks through experienced auditors and its A-SCEND platform. Learn more at a-lign.com.

Portal ERP
Jul 30th, 2026
FinQuery names Ryan Grace as CRO.

FinQuery names Ryan Grace as CRO. As the company accelerates its expansion into debt and fixed asset accounting, the market leader taps a $1B-exit veteran to scale its multi-product growth Redação Portal ERP Jul 30, 2026 T | Fonte: 18px FinQuery announced the appointment of Ryan Grace as Chief Revenue Officer. In his new role, Grace will oversee go-to-market strategy as the company expands its AI-powered subledger Platform, the system of record for corporate financial obligations and capital assets, including leases, fixed assets, debt and accruals. The strategic addition comes as FinQuery accelerates its product roadmap to support corporate accounting and finance teams across a wider spectrum of complex balance sheet requirements. Grace will lead commercial execution as the company scales its multi-product Platform to capture broader market share. Grace joins FinQuery following three and a half years as CRO at A-LIGN, where he built the high-velocity revenue organization that culminated in the company's $1B+ exit to Hg Capital in 2025. Over his career, Grace has specialized in scaling multi-product revenue operations and turning partnership ecosystems into primary growth engines, including playing a key role in HERO's acquisition by Klarna. "FinQuery has built an incredible foundation of customer trust by solving some of the most complex challenges in accounting," said Joe Schab, CEO of FinQuery. "As we continue to accelerate our product roadmap and deliver broader value to our clients, we need a revenue leader who knows how to scale multi-product organizations. Ryan has proven time and again that he knows how to capture market share at this exact stage of growth." Grace's appointment comes during a period of significant corporate momentum. Following a majority growth investment from TA Associates, the company has strategically built out its executive bench, recently adding Chief Marketing Officer Jake Fabbri and SVP of Customer Success Mike Gerson. "I'm joining FinQuery at a true inflection point - the kind of moment where a team can multiply its impact," said Ryan Grace, newly appointed CRO. "FinQuery has earned something most tech companies never achieve: genuine customer trust. That trust is our permission slip for what comes next. Leases were the wedge; total financial obligations are the market. My job is to build a go-to-market engine that matches the massive ambition of our product portfolio, ensuring our existing customers continue to feel flawlessly served while we move fast." Redação Portal ERP. Editorial Team

Kiteworks
Jul 22nd, 2026
Kiteworks and A-LIGN partner to strengthen cybersecurity across the Defense Industrial Base.

Kiteworks and A-LIGN partner to strengthen cybersecurity across the Defense Industrial Base. Partnership helps organizations protect sensitive data, strengthen cyber resilience, and prepare for evolving compliance requirements, including CMMC 2.0. San Mateo, California | July 22, 2026 Kiteworks, which empowers organizations to effectively manage risk in every send, share, receive, and use of private data, today announced a strategic partnership with A-LIGN, a leading CMMC Third Party Assessor Organization (C3PAO), to help Defense Industrial Base (DIB) organizations strengthen their cybersecurity posture and navigate the path to CMMC 2.0 Level 2 certification. The Department of War suspended CMMC Phase II on July 13, 2026, and launched a 60-day review of the program, but the underlying responsibility has not changed: Phase I self-assessment requirements and DFARS 252.204-7012 obligations remain fully in force. The DoW has been explicit that it is reducing red tape, not cybersecurity expectations. Protecting the Controlled Unclassified Information handled by tens of thousands of DIB organizations remains essential to defending the supply chain against increasingly sophisticated threats. The Kiteworks and A-LIGN partnership is built around a shared goal of helping DIB contractors protect that data, whether they are beginning to build out their data exchange controls or already in the assessment process and stalled on control gaps or evidence deficiencies. Organizations deploy the Kiteworks Control Plane to implement a substantial majority of CMMC Level 2 requirements out of the box, covering domains that commonly surface as evidence gaps in third-party assessments. Then, they can separately engage A-LIGN to independently assess that evidence through its rigorous assessment process. A-LIGN's role in this partnership is limited to independent assessment: A-LIGN does not consult, remediate, or advise on control implementation, and DIB organizations remain free to engage any authorized or accredited C3PAO. Kiteworks is FedRAMP High In Process and FedRAMP Moderate Authorized, with nine consecutive years of annual 3PAO audits validating 325 NIST 800-53 controls since 2017. The platform is FIPS 140-3 validated and deploys as a hardened single-tenant virtual appliance, eliminating the CUI isolation failures that are among the most common reasons DIB organizations require remediation cycles before earning CMMC certification. In addition, Kiteworks supports Hold Your Own Key (HYOK) encryption, giving DIB customers full ownership of their cryptographic keys and reducing audit scope and third-party exposure. "Protecting the DIB was never about a single deadline, but rather about building data security practices durable enough to hold up no matter how the compliance timeline evolves," said Kurt Michael, Chief Revenue Officer, Kiteworks. "Kiteworks and A-LIGN share that same vision. Through our partnership, Kiteworks helps organizations put comprehensive controls at the data layer, and A-LIGN, a top C3PAO, brings the experience and rigor to help validate that work through independent assessment. Whether an organization is early in the process or already underway, Kiteworks helps them get the right controls in place so they can walk into the assessment room prepared." A-LIGN is one of the leading C3PAOs in the market and has conducted nearly 100 CMMC Level 2 assessments across DIB organizations of every size. The firm's assessors cover the full scope of CMMC Level 2, including the governance, personnel, physical, and organizational controls. Beyond CMMC, A-LIGN is also one of the top three FedRAMP assessors, with a team of auditors with deep, firsthand familiarity with how federal agencies expect compliance evidence to be documented and defended. "There's some uncertainty right now about when, and in what form, CMMC's third-party assessment requirements will return from the Department's review, but the underlying requirements haven't gone anywhere," said Nicholas Ludy, Chief Growth Officer, A-LIGN. "The commitment to securing the DIB doesn't hinge on any single implementation date. As CMMC requirements evolve, Kiteworks will keep giving DIB organizations a practical path to stronger data security and audit readiness, and A-LIGN will continue to deliver rigorous, independent assessments, so organizations are prepared whenever the certification timeline is finalized." About Kiteworks Kiteworks' mission is to empower organizations to effectively manage risk in every send, share, receive, and use of private data. The Kiteworks platform provides customers with a secure data exchange that delivers data governance, compliance, and protection in a unified control plane. Kiteworks unifies, tracks, controls, and secures sensitive data moving within, into, and out of their organization, significantly improving risk management and ensuring regulatory compliance on all private data exchanges. Headquartered in Silicon Valley, Kiteworks protects over 100 million end-users and thousands of global enterprises and government agencies. About A-LIGN A-LIGN is the leading cybersecurity compliance partner, trusted by over 6,400 organizations worldwide to navigate the complexities of compliance, audit, and risk. With a tech-enabled delivery model and deep domain expertise, A-LIGN has completed more than 36,000 audits. It is the #1 issuer of SOC 2 reports and a top three FedRAMP assessor. Founded in 2009, A-LIGN delivers high-quality, efficient audits across frameworks including SOC 2, ISO 27001, FedRAMP, CMMC, ISO 42001, PCI, and HITRUST. To learn more, visit: https://www.a-lign.com. Additional Resources A-LIGN's recognition of this partnership does not constitute or imply partiality in its assessment activities. As a CMMC Third-Party Assessment Organization (C3PAO), A-LIGN applies the same rigor, scrutiny, and standardized processes to all assessments regardless of an organization's RPO affiliation, technology platform, or partner status. A-LIGN maintains a diverse portfolio of partnerships expressly to prevent any single relationship from creating dependencies that could impair its professional judgment, objectivity, or independence. All assessments are conducted in strict accordance with CMMC assessment guidelines and its impartiality obligations. A-LIGN provides assessment services only. It does not consult, remediate, or advise on control implementation; CMMC certification outcomes are determined solely by independent evaluation of evidence against 32 CFR Part 170 and NIST SP 800-171; and DIB organizations may engage any Authorized or Accredited C3PAO. Get started. It's easy to start ensuring regulatory compliance and effectively managing risk with Kiteworks. Join the thousands of organizations who are confident in how they exchange private data between people, machines, and systems. Get started today.

PR Newswire
May 21st, 2026
Optro, Crowe and A-LIGN launch end-to-end CMMC solution ahead of November 2026 deadline

Optro, formerly AuditBoard, has partnered with Crowe and A-LIGN to provide an end-to-end solution for organisations seeking Cybersecurity Maturity Model Certification (CMMC) ahead of the November 2026 deadline. Without certification, organisations cannot contract with the US Department of Defense. The solution creates a coordinated ecosystem where Crowe helps interpret requirements and build compliance programmes, Optro enables implementation through its AI-powered GRC platform, and A-LIGN conducts official assessments. The partnership aims to help thousands of organisations currently contracting with the Department of Defense meet the certification requirements. Optro serves more than 50% of the Fortune 500 and was named a Leader in Gartner's 2025 Magic Quadrant for GRC Tools.

Recently Posted Jobs

Sign up to get curated job recommendations

A-LIGN is Hiring for 19 Jobs on Simplify!

Find jobs on Simplify and start your career today

Don't see your dream role? Check out thousands of other roles on Simplify. Browse all jobs →